CVE-2023-47994: Integer Overflow
Published Jan 9, 2024
·Updated
An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run arbitrary code.
Affected Software
1 affected component
Freeimage Project Freeimage=3.18.0
Event History
Jan 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-47994?
CVE-2023-47994 is classified as a high-severity vulnerability due to its potential to allow remote code execution and denial of service.
2
How do I fix CVE-2023-47994?
To remediate CVE-2023-47994, update FreeImage to version 3.18.1 or later where the vulnerability has been patched.
3
What systems are affected by CVE-2023-47994?
CVE-2023-47994 specifically affects FreeImage version 3.18.0.
4
What types of attacks can be executed using CVE-2023-47994?
CVE-2023-47994 can be exploited to obtain sensitive information, cause denial of service, or run arbitrary code.
5
What function in FreeImage is vulnerable in CVE-2023-47994?
The integer overflow vulnerability in CVE-2023-47994 is found in the LoadPixelDataRLE4 function within PluginBMP.cpp.